PageShield
Back to dashboard

Terms of Service

Last updated: July 15, 2026 (version 2026-07-15b) · Applies to the PageShield service operated by CRAFTAC SRL

These Terms of Service ("Terms") are a legal agreement between you ("Customer", "you" or "your") and CRAFTAC SRL, a limited liability company incorporated under Romanian law, registered with the Romanian Trade Register under no. J22/725/2024, having unique identification code (CUI) 49662167, with its registered office at Str. Bisericii 9, Bl. 65, Sc. A, Et. 4, Ap. 15, Cod 707085, Sat Lunca Cetatuii, Judetul Iasi, Romania ("PageShield", "we", "us" or "our"). These Terms govern your access to and use of the PageShield website, dashboard, Protection Snippets, pixel fallback, APIs where made available, alerts, webhooks, documentation and related services (together, the "Service").

By clicking to accept these Terms, or by completing a registration, trial, Subscription or feature-activation flow that clearly presents these Terms and requires acceptance, you enter into a binding agreement with us. Once accepted, these Terms govern your continued access to and use of the Service. If you act on behalf of a company, organisation, store, brand or other legal entity, you represent that you have authority to bind that entity, and "Customer" refers to that entity. If you do not have that authority, or do not agree to these Terms, you must not create an Account or use the Service.

The Refund & Cancellation Policy, the Data Processing Addendum ("DPA") where applicable, and the PageShield EU Data Act Addendum where applicable are incorporated into and form part of these Terms. Each incorporated document will be identified by its title and effective date or version on the PageShield legal pages, in the dashboard, at checkout or through another durable electronic method when it is made available to you. The version made available when you accept these Terms forms part of your agreement. A later version applies only in accordance with applicable law, Section 22 and any valid update mechanism stated in that document. The Privacy Policy explains how personal data is processed in connection with the Service. It is provided as a transparency notice and does not form part of these Terms, except to the extent expressly required by applicable law or expressly stated in the Privacy Policy.

If there is a conflict between these Terms and another contractual document incorporated into them, the DPA controls only in relation to the processing of Customer Personal Data on behalf of the Customer, the Refund & Cancellation Policy controls only in relation to cancellation and refund eligibility or mechanics, and the EU Data Act Addendum controls only in relation to switching, portability, transition, retrieval and deletion matters within its stated scope. These Terms control in all other respects. Lemon Squeezy's applicable buyer, payment and privacy terms govern the payment transaction and Merchant of Record services only, as further described in Section 8. If you do not agree to these Terms, do not use the Service.

To the extent Romanian law requires separate express written acceptance of standard clauses that limit liability, permit unilateral suspension or termination, provide for automatic renewal, impose an indemnity, contain disclaimers, select governing law or courts, or otherwise qualify as unusual clauses, the PageShield interface presents a separate unticked acceptance control that specifically refers to, makes readily accessible and requires express acceptance of the relevant clauses in Sections 7, 10, 15, 16, 17, 18, 19, 21 and 22. PageShield records the Account, the accepted wording and version, and the date and time of acceptance. This separate acceptance does not validate a clause that is unfair, prohibited or otherwise unenforceable under mandatory Consumer law.

Definitions

Account: the account created to access and use the Service.

Affiliate: an entity that directly or indirectly controls, is controlled by, or is under common control with a party.

Billing Period: the recurring period for which a Subscription fee is charged, as displayed at checkout.

Business Customer: a Customer acting for purposes relating to its trade, business, craft or profession.

Consumer: an individual acting for purposes outside that individual's trade, business, craft or profession.

Customer Data: data, settings, configurations, protection profiles, domains, URLs, webhook destinations, Detection Event records, Heartbeat records, approximate location fields, technical classification results, notification-suppression rules and other information submitted by or for the Customer, or generated specifically for the Customer through use of the Service, excluding Service Usage Data.

Customer Personal Data: personal data, if any, that PageShield processes on behalf of the Customer in connection with the Service, as further described in the DPA.

Service Usage Data: technical, operational, diagnostic and statistical information generated through the operation, security, performance and use of the Service, including feature use, request volumes, error information and Plan-limit measurements. Service Usage Data excludes Customer Personal Data, Detection Event records and Heartbeat records when PageShield processes them on the Customer's behalf, but may include limited request or security metadata processed by PageShield as an independent controller for the purposes described in the Privacy Policy.

Detection Event: an event recorded when the Protection Snippet or pixel fallback appears to run on a domain other than the configured Protected Domain.

Classification Result: an informative bot, human or unknown label generated for an individual Detection Event from the user-agent string and a transient network signal.

Notification Suppression Rule: a Customer-configured rule that suppresses notifications for future Detection Events matching a customer-scoped pseudonymous identifier without disabling redirect functionality.

DPA: the PageShield Data Processing Addendum, where applicable.

EU Data Act Addendum: the PageShield EU Data Act Addendum, which applies only to the extent stated in that document.

Heartbeat: a limited signal sent from the Customer's original Protected Domain to confirm that the Protection Snippet is active and functioning under normal technical conditions.

Merchant of Record: an independent third party that contracts with the purchaser for the payment transaction as seller of record and handles payment processing, applicable transaction-related taxes, invoicing, refunds and chargebacks.

Plan: a free, trial or paid service configuration made available by PageShield with specified features, limits and pricing.

Protected Domain or Protected Page: a domain, page, funnel, store, landing page or other web property configured by the Customer in the Service.

Protection Snippet: the code generated for the Customer's Account, including any pixel fallback or related technical component provided by PageShield.

Redirect Destination: a URL or destination configured by the Customer to which traffic may be redirected when the Service detects an unauthorised copy.

Subscription: a paid, recurring right to access a Plan for the applicable Billing Period.

1. Intended use and Customer status

The Service is intended and optimised for business and professional use, in particular by online merchants, including e-commerce and dropshipping store owners, advertisers, agencies, brand owners and other commercial website operators who wish to protect web properties that they own, operate or are legally authorised to protect. The Service is not designed or marketed for purely personal, household or non-commercial use.

Before accessing certain features, starting a trial or subscribing to a paid Plan, we may require you to confirm that you are acquiring and using the Service for business or professional purposes. You must provide accurate information and must not misrepresent your status or purpose of use.

A natural person who acquires or uses the Service for purposes relating to a trade, business, craft or profession is a Business Customer, even if that person uses a personal email address or individual payment method. If the Service is acquired or used for mixed purposes, you will be treated as a Consumer only where the business or professional purpose is not predominant under applicable law.

If, despite the intended business and professional nature of the Service, you qualify as a Consumer under mandatory applicable law, any provision of these Terms that expressly applies only to Business Customers does not apply to you, and nothing in these Terms limits or excludes any mandatory Consumer rights available to you under applicable law.

We may refuse registration, restrict features, suspend access or terminate access where we reasonably believe that the Service is being used outside its intended page-protection purpose or in a manner that creates legal, security, operational, reputational, payment, provider or third-party risk.

2. What the Service does

PageShield is a technical clone-detection and optional traffic-redirection SaaS service designed to assist Customers in recovering traffic from unauthorised copies of their pages. The Customer installs the Protection Snippet on pages it designates. The Service may then detect whether that snippet is running on an unexpected domain and, where enabled and technically possible, may redirect visitors from the detected copy back to a Redirect Destination configured by the Customer.

When the Protection Snippet runs correctly on the Customer's original Protected Domain, it may send a limited Heartbeat signal, designed to be sent no more than once per hour per browser/device under normal technical conditions, to confirm that protection is active. A Heartbeat may include limited technical fields such as Customer identifier, hostname and timestamp.

When a Detection Event occurs, the Service may record technical metadata such as hostname, URL, referrer, user-agent, timestamp and redirect status. It may also use the request's raw IP address transiently in memory to derive an approximate country and city through a locally hosted MaxMind GeoLite2 City database, obtain an ASN through a locally hosted MaxMind GeoLite2 ASN database, generate a daily deduplication identifier and compare a customer-scoped Notification Suppression Rule. No live external geolocation or IP-intelligence API is used for these functions. The raw IP address, ASN, internal ASN-list match result and data-centre/residential signal are not retained as Detection Event fields, and the raw IP address used for this flow is not recorded in application or infrastructure logs generated for the Detection Event flow. Separate routine logs for other Service activities may process IP addresses as described in the Privacy Policy.

The Service may assign a bot, human or unknown Classification Result using the user-agent string and a transient ASN-based network signal. PageShield checks the locally obtained ASN against a locally stored, manually maintained list of known cloud or hosting providers. The list is not dynamically populated from an external service and may be reviewed and updated by PageShield from time to time. For this heuristic only, a listed ASN is treated as a data-centre signal and an unlisted ASN as a non-data-centre or residential-ISP signal. No additional external API or database is used. Only the Classification Result is retained with the Detection Event; the ASN, list-match result, network signal and other technical reasons are not retained. The result is an estimate and does not establish a person's identity, residence, intent, connection type or legal status.

To the extent that the per-event Classification Result constitutes profiling under applicable data-protection law, it is limited to technical categorisation of that Detection Event. PageShield does not use the result to infer broader personal characteristics, create a persistent behavioural profile, combine a source profile across Customers or make a decision producing legal or similarly significant effects for an individual.

Webhook alerts are available only on the Pro and Business Plans. The webhook payload is a generic teaser directing the Customer to review the dashboard and does not include the full URL, referrer, user-agent string, IP address or protection-profile name. If delivery fails, PageShield makes three automatic retries after approximately five (5) seconds, thirty (30) seconds and two (2) minutes. After the final failed attempt, the failure is recorded in an error log retained in accordance with the Privacy Policy, without interrupting the remaining Service functionality.

A Detection Event, approximate location and Classification Result are technical signals only. They do not establish that a page is unlawful, infringing or unauthorised, that a visitor is a bot or human with certainty, or that a network is residential. They may result from an authorised mirror, proxy, VPN, shared network, preview, staging environment, cache, content-delivery configuration or other legitimate technical arrangement.

The Service is a technical tool. It is not a legal enforcement, takedown, anti-counterfeiting, litigation, intellectual property enforcement, investigation or legal advice service. We do not guarantee removal of cloned pages, identification of infringers, recovery of traffic, recovery of revenue, prevention of all unauthorised copying or any specific commercial, legal or technical outcome.

3. Account registration and account security

You must provide accurate and complete Account information, including a valid email address, and keep that information up to date. You are responsible for maintaining the confidentiality of your credentials, devices, sessions, tokens and access to your Account.

You are responsible for all activity under your Account and for the acts and omissions of all users, team members, contractors, employees, agents or other persons whom you authorise to access the Service through your Account, dashboard, tokens, API access or configurations. You must ensure that each authorised user complies with these Terms.

Account credentials must be assigned to and used only by authorised persons. You must not share credentials publicly or permit access in excess of the user or seat limits applicable to your Plan.

You must be at least 18 years old, or the age of legal majority in your jurisdiction, to create an Account or use the Service. If you create an Account for an organisation, you represent that you have authority to act on its behalf and to bind it to these Terms.

You must notify us promptly at support@pageshield.io if you become aware of unauthorised access to your Account or any suspected security incident affecting your use of the Service. You must take reasonable steps to secure the Account, including using strong credentials, maintaining secure devices and revoking access that is no longer required.

4. Customer authority over protected pages and domains

You may use the Service only on domains, pages, stores, funnels or other web properties that you own, operate or are otherwise legally authorised to protect. You must not install, configure, deploy or use the Service on, against or in relation to any domain, page, store, funnel, account, platform or web property that you do not own, control or have legal authority to protect.

For each protection profile, Protected Domain, protected URL, Redirect Destination, webhook endpoint and related configuration, you confirm and, if you are a Business Customer, represent, warrant and undertake that:

(a) you have all rights, permissions, authorisations and legal bases required to configure and use the Service in that manner;

(b) your use of the Service does not infringe the rights of any third party, including intellectual property, privacy, data protection, confidentiality, consumer protection, unfair competition or electronic communications rights;

(c) you will provide all notices, disclosures and consents required by applicable law in relation to your websites, visitors, customers and use of the Protection Snippet, including where localStorage or similar technologies are used;

(d) you are solely responsible for the content, legality, destination, safety and accuracy of any Protected Page, Redirect Destination, webhook endpoint or configuration you provide; and

(e) you will keep your Protected Domains, authorised domains, exclusions and related configuration accurate and up to date, including for legitimate mirrors, staging environments, proxies, previews and content-delivery arrangements.

We may request reasonable evidence that you own, control or are authorised to protect any domain, page, Redirect Destination, webhook endpoint or related web property configured in the Service. We may suspend, disable or restrict the relevant protection profile, redirect, webhook, snippet or Account until such evidence is provided and verified to our reasonable satisfaction. Where reasonably practicable, we will limit the restriction to the affected configuration or feature.

5. Protection Snippet, Heartbeat, localStorage, redirects and Customer configuration

The Protection Snippet and any pixel fallback are provided solely for use within the Service and subject to these Terms. You are responsible for installing the snippet correctly, keeping your Protected Domains and settings accurate, and ensuring that your website, platform, content management system, third-party scripts and technical environment allow the snippet to operate as intended.

The Protection Snippet does not set cookies and is not intended for advertising tracking, behavioural advertising or cross-site profiling. It does not actively collect additional browser or device attributes commonly used for fingerprinting, such as canvas, WebGL, installed-font, hardware or similar high-entropy signals, and it does not create a persistent cross-site visitor identifier. It may use localStorage on the Customer's page solely to limit the frequency of Heartbeat signals so that such signals are not sent more often than intended under normal technical conditions. LocalStorage and similar browser technologies may be subject to applicable ePrivacy or terminal-equipment rules even where no cookies are used. The geolocation, ASN lookup, classification, daily deduplication and notification-suppression functions are performed server-side from request metadata and do not add cookies or localStorage entries or actively collect additional browser/device fingerprinting attributes.

You are responsible for determining whether your use of the Protection Snippet, Heartbeat functionality, redirect functionality, localStorage or similar technologies requires notices, disclosures, consents or other compliance measures under laws applicable to your own websites, visitors and jurisdictions. You are also responsible for ensuring that your privacy, cookie, localStorage, tracking or similar technology notices accurately describe the use of the Protection Snippet where required.

We do not routinely review or approve Protected Domains, Detection Events, Heartbeat data, Redirect Destinations, schedules, percentages, triggers, webhook endpoints or other Customer configurations before they go live. You remain solely responsible for the legality, accuracy, safety and consequences of your configurations.

You are responsible for enabling, reviewing and removing Notification Suppression Rules and any option that suppresses notifications based on a Classification Result. A Notification Suppression Rule is applied only within the Customer scope in which it was created and is not used for another Customer or to create a global IP-reputation list. Unless removed earlier by you, the rule remains active for ninety (90) days from creation or from the most recent matching Detection Event, whichever is later. A suppression rule affects notifications only; it does not disable Detection Event recording where otherwise applicable and does not disable or alter redirect functionality. You must not treat a Classification Result as a definitive determination of identity, intent, fraud or unlawfulness. A matching Detection Event restarts the ninety-day period, so the rule may remain active for longer than ninety days while matching continues.

We may apply automated or manual security, abuse-prevention and domain-verification controls and may block, disable or require verification of a Redirect Destination or configuration that appears unsafe, unauthorised, deceptive or inconsistent with these Terms.

Before enabling redirect functionality for a detected domain, you must take reasonable steps to verify that the Detection Event concerns an unauthorised copy and not a legitimate technical or commercial arrangement. If you are uncertain, you should use monitoring or alert functionality without enabling a redirect until the situation is verified.

If we receive a credible complaint that a Protected Domain, detected domain, Redirect Destination or related configuration is authorised, legitimate, incorrectly identified or otherwise disputed, we may temporarily disable the affected redirect or protection profile while we review the available information. You must cooperate with the review and provide reasonable evidence of your rights or authority upon request. PageShield is not required to adjudicate intellectual property, ownership or other legal disputes between you and a third party and may keep the affected functionality disabled until sufficient evidence is provided or the dispute is otherwise resolved.

You must not configure a Redirect Destination that is unlawful, fraudulent, misleading, harmful, malicious, infringing, deceptive, unsafe, unrelated to the Protected Page or likely to expose us or any third party to legal, security, operational or reputational risk.

6. Acceptable use

You must use the Service lawfully, responsibly and only for the purpose of protecting web pages that you are authorised to protect. You must not:

(a) monitor, detect, redirect or interfere with traffic on websites or domains belonging to third parties without legal authority;

(b) use the Service against a competitor's legitimate independently operated website, as opposed to an unauthorised copy of your own page;

(c) use the Service for fraud, phishing, malware, deception, harassment, unlawful tracking, unauthorised surveillance, unlawful traffic manipulation or unfair competition;

(d) capture, divert, manipulate or interfere with traffic unless you have a lawful right to do so;

(e) use the Service to collect or process personal data beyond the limited technical metadata that the Service is designed to process;

(f) intentionally insert personal data, payment details, order details, authentication tokens, health data, children's data, special category data or other sensitive information into URLs, referrers, webhook endpoints or configuration fields;

(g) probe, scan, attack, overload, bypass rate limits, bypass Plan limits or attempt to gain unauthorised access to the Service or another user's data;

(h) use bots, crawlers, scrapers or other automated means to access, copy, monitor or extract data from the Service, except through an API or functionality expressly made available for that purpose and in accordance with our documentation and applicable limits;

(i) reverse engineer, decompile or disassemble the Service, except to the limited extent expressly permitted by mandatory applicable law;

(j) resell, sublicense, white-label or make the Service available to third parties without our prior written consent;

(k) use the Service in a way that violates applicable privacy, data protection, ePrivacy, electronic communications, consumer protection, intellectual property, anti-spam, cybersecurity, export control, sanctions, unfair competition or other laws;

(l) use the Service in a way that violates the terms, policies or technical restrictions of any e-commerce platform, advertising platform, payment provider, hosting provider, domain registrar, marketplace, app store or other third-party service used by you;

(m) use the Service in violation of applicable sanctions or export-control laws, including by or for a person, entity, territory, activity, product or service subject to a prohibition applicable to you or to us; or

(n) use the Service in a way that could damage, disable, overburden, impair or compromise the Service, our infrastructure, our providers or any third party.

We may investigate suspected violations and may suspend, restrict or terminate access immediately where we reasonably believe that continued access creates legal, security, operational, reputational or third-party risk.

7. Plans, free trial and Subscriptions

7.1 Electronic contracting process

Before you submit an order, the interface identifies the selected Plan, Billing Period, total price, renewal terms, trial terms and contractual documents incorporated into the order. You can review and correct the information entered before submitting the order. The interface separately records acceptance of these Terms, any express acceptance required for unusual standard clauses under Romanian law and, for a Consumer, any express request that paid performance begin during the statutory withdrawal period.

Where an order requires payment, immediately before the order is submitted, the applicable checkout displays clearly and prominently the principal characteristics of the selected Service and Plan, the total price inclusive of applicable taxes and mandatory charges, the Billing Period, the duration of the Agreement, the automatic-renewal arrangement, any minimum contractual commitment and the applicable cancellation or termination conditions. The available payment methods and any applicable geographical, technical or Account restrictions are displayed no later than the beginning of the ordering process.

Where a Consumer places a paid order, the final button or similar ordering function is labelled “Order with an obligation to pay” or with another clear and unambiguous equivalent permitted by applicable law. A Consumer is not bound by a paid order where the legally required acknowledgement that the order entails an obligation to pay has not been provided.

A contract is concluded when PageShield or Lemon Squeezy, acting as Merchant of Record for the payment transaction, confirms acceptance of the order electronically, subject to any verification stated in the ordering flow. PageShield sends or makes available without undue delay an electronic acknowledgement and the applicable contractual documents on a durable medium. PageShield stores the accepted document versions, order confirmation and acceptance records and makes them available through the Account or on request for the applicable retention period.

The contracting language is English unless the interface expressly offers another language. The review and editing controls allow input errors to be identified and corrected before submission. PageShield does not subscribe to a code of conduct governing the electronic contracting process unless the checkout or legal pages expressly state otherwise.

The Service configurations offered at the effective date include the Starter free tier and the paid Pro and Business Plans. Prices, included features, usage limits, dashboard visibility windows, export availability and rate limits are those displayed on the pricing page, inside the dashboard or at checkout when you place an order. PageShield may introduce, rename, replace or discontinue Plans in accordance with these Terms and applicable law.

Plan and technical limits form part of the Service configuration. We may enforce those limits automatically, throttle excessive traffic, restrict abusive usage or require an upgrade where usage exceeds the intended scope of a Plan.

Dashboard history access windows determine what records are visible through the relevant Plan. Starter provides read-only access to up to seven (7) days of Detection Event history and does not include CSV export, including where the Account previously had a paid Subscription. Pro provides access to up to ninety (90) days. Business has no Plan-based dashboard history window while the Business Subscription remains active. These feature and access rules do not state how long underlying data is retained or when it is deleted. Data retention and deletion are described in the Privacy Policy and, where applicable, the DPA.

The retention schedule is separate from Plan visibility: Heartbeat records are retained for thirty (30) days; complete Detection Event technical metadata is retained for ninety (90) days; after that period, fields and combinations of fields reasonably capable of identifying, singling out or linking an individual are deleted or irreversibly anonymised. Detection Event data, including approximate country, city and Classification Result, is deleted or irreversibly anonymised ninety (90) days after creation, with no conditional extension. The Privacy Policy contains the complete retention schedule and applicable exceptions.

If a downgrade reduces the number of protection profiles permitted by the new Plan, PageShield does not delete the excess profiles. The oldest profiles, determined by creation time, remain active up to the new Plan limit. Excess profiles remain visible in the Account but become inactive: their Protection Snippets do not perform detection or redirection and return an empty or otherwise harmless response. If the Customer later upgrades, inactive profiles are reactivated automatically in chronological creation order up to the new Plan limit.

When an active profile operates under the Starter free-tier configuration, the Plan applies its redirect behaviour automatically on page load to one hundred per cent (100%) of visitors. Monitor-only mode, configurable redirect percentages, click-based triggers, future activation schedules, pixel fallback, analytics and webhook alerts are disabled and ignored, even if earlier values remain stored in the Account. Service behaviour is recalculated from the applicable Plan rather than from previously saved paid-Plan settings. Before a Customer-initiated downgrade, PageShield displays a prominent summary of these effects. Where a paid Subscription is scheduled to expire or downgrade following cancellation, PageShield also provides reasonable advance notice by email, dashboard notice or another durable electronic method, unless the Customer has already received equivalent information or immediate action is required by law, security or payment status.

This product-level CSV restriction does not limit a verified statutory data-protection access or portability request or the Customer's return rights under the DPA, and it does not limit a switching or export right that applies under the EU Data Act Addendum.

Usage measurements and limit calculations are determined from our systems and records. If you reasonably believe that a measurement is materially incorrect, contact us promptly so that we can investigate.

Before you start a paid Subscription, the applicable price, Billing Period, renewal arrangement, trial conditions and cancellation method will be displayed through the checkout flow, dashboard or Merchant of Record interface.

For Consumers, where mandatory Consumer law applies, the checkout flow, Merchant of Record interface or other pre-contractual information made available before ordering displays the main characteristics of the Service, the total price including applicable taxes and mandatory charges, the Billing Period, renewal and trial conditions, cancellation methods, the electronic-contracting steps described above, complaint-handling information, the existence of the applicable legal conformity guarantee for digital services, the location of the dedicated online withdrawal function, the model withdrawal form in Annex 1 to the Refund & Cancellation Policy, and information on functionality, compatibility and interoperability required by law. The same information is provided or confirmed on a durable medium where required.

Where a Consumer requests that a paid Service begin during the statutory withdrawal period, PageShield obtains a separate express request, distinct from acceptance of these Terms and acknowledgement of the Privacy Policy, and records the wording accepted, the Account or contract reference, and the date and time. The notice explains that the Consumer may owe a proportionate amount for the Service supplied before withdrawal and that the withdrawal right is lost only after the Service has been fully performed where all statutory conditions are met. PageShield also provides the dedicated online withdrawal function and electronic confirmation process described in the Refund & Cancellation Policy.

New Accounts may be eligible for a seven-day free trial of a paid Plan. No payment method is required to start the trial. The trial does not automatically convert into a paid Subscription, and you will not be charged when it ends. Unless you subscribe before the trial ends, the Account reverts to the free-tier limits then applicable. The trial expiry date and principal trial features will be displayed in the dashboard or other trial interface.

Unless the checkout states otherwise, a free trial is limited to one per Customer. We may refuse, shorten or end a trial where we reasonably believe that multiple Accounts, false information or other means are being used to obtain repeated or unauthorised trial access.

Paid Subscriptions renew for successive monthly Billing Periods, unless the checkout expressly states another Billing Period, until cancelled. By subscribing, you authorise recurring charges for the selected Plan through the Merchant of Record. For Consumers, recurring payment and renewal information must be presented clearly before the order is placed, and a paid Subscription will begin only where the Consumer has taken the required ordering action through the checkout flow.

Cancellation prevents future renewal but does not normally end access before the end of the active paid Billing Period, except where access is suspended or terminated under Section 16.

Changes to Plans and paid features will apply prospectively in accordance with Section 22. A price increase for an existing paid Subscription will normally take effect no earlier than the next renewal date following reasonable advance notice, unless an earlier change is required by applicable law, a tax change or a Merchant of Record requirement. You may cancel before the new price takes effect.

8. Payments, billing and Lemon Squeezy

For every paid purchase and recurring Subscription transaction, Lemon Squeezy acts as the Merchant of Record and seller of record. Lemon Squeezy contracts with the purchaser for the payment transaction and handles checkout, collection of amounts due, recurring billing, payment-method processing, applicable transaction-related taxes, invoicing, refunds, chargebacks, payment disputes and related transaction administration. The purchase transaction is subject to Lemon Squeezy's applicable buyer, payment and privacy terms.

CRAFTAC SRL remains the provider and licensor of the PageShield Service and is responsible for providing access to and operating the Service in accordance with these Terms. Lemon Squeezy does not operate the Service and CRAFTAC SRL does not replace Lemon Squeezy as the seller or payment counterparty for a paid transaction.

All amounts payable for a paid Subscription are charged and collected through Lemon Squeezy. Payment-method processing, transaction-related tax calculation and collection, invoicing, billing administration, refunds and chargebacks are handled through Lemon Squeezy. CRAFTAC SRL does not directly collect or store your full payment-card details and does not issue a refund or transaction reversal outside the Merchant of Record systems.

Lemon Squeezy is responsible for transaction-related sales tax, VAT or similar indirect taxes to the extent stated in its applicable terms and reflected at checkout or on the invoice. You remain responsible for taxes, duties, reporting or other fiscal obligations arising from your own business, income, accounting treatment or use of the Service.

We receive from Lemon Squeezy only the Subscription and billing metadata reasonably necessary to activate, manage, suspend, resume or terminate access to the Service and to provide transaction support, such as customer identifier, Subscription identifier, Plan, payment or Subscription status, renewal date and related metadata.

You are responsible for ensuring that the information supplied to Lemon Squeezy is accurate and that you are authorised to use the selected payment method. To the maximum extent permitted by law, CRAFTAC SRL is not responsible for payment failures, card-issuer or bank decisions, currency conversion, payment-provider outages, delayed settlement, invoice generation or other Merchant of Record processing matters outside its reasonable control.

If Lemon Squeezy reports that a payment has failed, been reversed, appears fraudulent or unauthorised, or is subject to a chargeback or payment dispute, we may suspend, downgrade or restrict the affected paid features while the matter is handled through the applicable Merchant of Record process, to the extent permitted by applicable law. We will not treat the good-faith exercise of a mandatory Consumer right as abuse.

9. Intellectual property, Customer Data and licence

PageShield and its licensors retain all rights, title and interest in and to the Service, including software, source and object code, Protection Snippets, APIs, interfaces, documentation, designs, trademarks, trade names, detection logic, security methods, databases, models, workflows, know-how and all improvements, modifications and derivative works. Except for the limited right to use the Service under these Terms, no right is granted to you by implication, estoppel or otherwise.

Subject to these Terms and payment of applicable fees, PageShield grants you a limited, non-exclusive, non-transferable, non-sublicensable and revocable right during the applicable Account or Subscription term to access and use the Service and install the Protection Snippet solely on web properties that you are authorised to protect. This right ends when your authorised access to the affected Service ends.

As between the parties, you retain all rights in Customer Data. You grant PageShield a worldwide, non-exclusive, royalty-free licence, for no longer than reasonably necessary, to host, copy, transmit, structure, display, technically format, secure, back up and otherwise process Customer Data solely to provide, operate, maintain, support, troubleshoot and secure the Service, comply with your documented instructions, administer the Agreement and comply with law. PageShield does not use Customer Personal Data processed on your behalf for an independent product-improvement purpose unless you have given a documented instruction or another lawful basis applies. This licence does not transfer ownership of Customer Data.

PageShield may use Service Usage Data and may create and use aggregated or irreversibly anonymised information that no longer identifies the Customer or any individual for security, analytics, capacity planning, service improvement and business administration. PageShield will not attempt to re-identify information that it has treated as irreversibly anonymised.

You must not remove or obscure proprietary notices, copy or distribute the Service except as expressly permitted, or use PageShield names, marks or branding without prior written permission. Any feedback or suggestion you voluntarily provide may be used by PageShield without restriction or obligation, provided that PageShield does not publicly identify you as the source without permission.

10. Availability, maintenance and Service changes

We aim to provide a reliable Service, but we do not guarantee uninterrupted, error-free or always-available operation, and no online service can be guaranteed to be completely secure. The Service may be unavailable or degraded due to maintenance, updates, provider outages, network failures, attacks, browser behaviour, third-party changes, legal requirements or events beyond our reasonable control. Where reasonably practicable, we will provide advance notice of scheduled maintenance expected to cause material disruption.

Unless we agree otherwise in a separate written agreement, the Service is not provided with a specific service-level agreement, uptime commitment, incident response time, support response time or maintenance window. Support is provided on a reasonable-efforts basis.

We may modify, update, suspend, discontinue or replace features of the Service where reasonably necessary for security, reliability, legal or regulatory compliance, prevention of fraud or abuse, technical compatibility or interoperability, maintenance, infrastructure or provider changes, adaptation to usage or capacity, or the responsible discontinuation or replacement of functionality. We will not materially reduce core paid functionality during an active paid Billing Period without applying the notice, termination and refund protections set out in Sections 16 and 22, subject to urgent legal, security or provider requirements and mandatory Consumer law.

If we expressly identify a feature as experimental, beta, preview or early access, that feature may be incomplete, may contain errors and may be modified or discontinued. Unless we expressly agree otherwise in writing, such a feature is provided for evaluation without a specific availability, support or performance commitment and should not be relied upon for critical operations.

We may use hosting, DNS and security, payment, support, email delivery, uptime monitoring, error monitoring, logging, backup and other operational providers to deliver and secure the Service. Providers may change over time. Where such changes involve personal data, they will be handled as described in the Privacy Policy and, where applicable, the DPA.

Cloudflare provides authoritative DNS and basic DNS-layer protection. It is not configured as an application reverse proxy, and application, API, Protection Snippet, detection and other Service payloads are sent directly to the Hetzner-hosted environment. Cloudflare may process limited Account, zone and DNS-operational data under its applicable documentation. PageShield will reassess the relevant role and update the documentation before enabling proxying or another Cloudflare service that materially changes processing.

11. Detection, Heartbeat and redirect limitations

Clone detection depends on technical conditions that may be outside our control. A cloned page may not be detected if a third party removes, modifies, blocks, strips, disables or prevents execution of the Protection Snippet or pixel fallback, if a page is dynamically rendered, proxied, altered, protected by third-party scripts or browser restrictions, or if other technical conditions prevent detection. Detection Events may be delayed, incomplete, duplicated or false positives.

IP-based country and city results are approximate and may be unavailable or inaccurate. ASN-based matching checks whether an ASN appears on PageShield's locally stored, manually maintained list of known cloud or hosting providers, which is not dynamically populated from an external service and may be updated from time to time. A list match is only a data-centre signal, and a non-match is only a non-data-centre or residential-ISP signal for the classification heuristic; neither proves the actual connection type or that a visitor is a bot or human.

Classification Results may be false, incomplete or unknown. Notification Suppression Rules may fail to match because an IP address changes, is shared, is translated, is proxied or is otherwise presented differently. They may also suppress a notification associated with a different person using the same IP address. You remain responsible for reviewing dashboard information and configuring suppression appropriately.

Heartbeat functionality is intended to provide a limited signal that the Protection Snippet is active on the Customer's original Protected Domain. A missing, delayed or failed Heartbeat does not necessarily mean that protection is absent, and a successful Heartbeat does not guarantee detection of future clones or successful redirect behaviour.

Redirect functionality depends on the current Plan, Customer configuration, browser behaviour, network conditions, third-party code, page structure and execution of the Protection Snippet. On paid Plans, relevant configuration may include mode, trigger, percentage and schedule settings. Under the Starter free-tier configuration, an active profile applies the Plan-defined redirect automatically on page load to all visitors and ignores advanced settings saved under a previous paid Plan. We do not guarantee that a redirect will complete, be accepted by every browser or platform, or produce any particular commercial result.

We do not guarantee detection of every clone, recovery of traffic or revenue, prevention of reputational or advertising loss, removal of infringing pages, identification of infringers, legal or platform enforcement, conversion recovery or any specific business outcome.

12. Data protection, privacy and local legal compliance

Our Privacy Policy describes how we process personal data when operating the Service. To the extent PageShield processes Customer Personal Data on your behalf, the DPA applies. You are responsible for determining your own role and obligations under applicable privacy, data-protection, ePrivacy, terminal-equipment and electronic-communications laws.

You must determine and document a valid legal basis and provide legally required notices, disclosures, consents or other controls before installing or enabling the Protection Snippet or related functionality. This includes accurately addressing localStorage, Heartbeats, Detection Events, transient IP processing, approximate country/city derivation, bot/human/unknown classification, notification suppression, redirects, webhooks and the collection or derivation of visitor data from detected pages where required. PageShield's documentation and Privacy Policy do not replace notices or assessments that you must provide or perform for your own processing, including any applicable legitimate-interest assessment and the transparency analysis required under Articles 13 and/or 14 GDPR, as applicable.

Before enabling the relevant functions, you must assess whether the envisaged processing is likely to result in a high risk and therefore requires a data-protection impact assessment and, where applicable, prior consultation. That assessment should take account of the nature, context, scale and systematic character of the processing, including any processing of traffic or location-related data. You must also assess whether the Protection Snippet request or transmission falls within Article 5(3) of the ePrivacy Directive or an equivalent national rule; the absence of cookies does not by itself determine whether consent or a statutory exception is required.

You must not enable or continue an affected feature in a jurisdiction or configuration where you cannot establish and maintain the required legal basis, ePrivacy or terminal-equipment consent or exception, transparency, rights-handling and risk-assessment measures. PageShield may suspend the affected feature where reasonably necessary to avoid processing that appears unlawful or materially non-compliant.

You must not intentionally configure the Service to process special-category data, children's data, payment-card data, authentication secrets, order or checkout content, health data or other sensitive information. URLs and referrers may contain information inserted by you, a visitor, a browser, a platform or a third party; you should minimise such information and avoid sensitive data in URLs and configuration fields.

If a conflict concerns processing, protection, transfer, return or deletion of Customer Personal Data, the DPA and mandatory Data Protection Laws prevail to the extent of that conflict.

13. Third-party services and Customer-controlled destinations

The Service may interoperate with or depend on third-party websites, hosting providers, browsers, e-commerce platforms, payment services, email services, webhooks, Redirect Destinations, APIs or other systems. PageShield does not control and is not responsible for the content, legality, availability, security, compatibility, performance, privacy practices or contractual terms of a third-party service selected or controlled by you.

The IP-enrichment data source currently used for the functions described in Section 2 consists of downloadable MaxMind GeoLite2 City and GeoLite2 ASN databases stored and queried locally on PageShield infrastructure. MaxMind does not receive live Detection Event IP addresses or Service payloads under this architecture. This statement does not make MaxMind responsible for the Service or for PageShield's classification logic.

A webhook endpoint, Redirect Destination, Customer website, integration or other destination selected by you is a Customer-controlled recipient. You are responsible for ensuring that you are authorised to send data or traffic to that destination and that the destination is secure, lawful and appropriately configured. PageShield is not responsible for processing that occurs after data or traffic has been delivered to the selected destination, without limiting responsibility that cannot lawfully be excluded for the transmission itself.

References or links to third-party services do not constitute endorsement. Your use of a third-party service is governed by your agreement with that third party.

14. Security

PageShield implements technical and organisational measures designed to provide a level of security appropriate to the risks of the Service and, where applicable, Customer Personal Data. Current measures are described in the Privacy Policy and DPA. No method of transmission, storage or online operation is completely secure, and no security measure can eliminate all risk.

You are responsible for securing your Account, credentials, devices, websites, Protection Snippets, Redirect Destinations, webhook endpoints, integrations and exported files. You must use strong credentials, limit access to authorised users, revoke access no longer needed, keep your systems reasonably updated and notify us promptly of suspected unauthorised access or misuse.

We may apply rate limits, verification controls, logging, monitoring, blocking, credential resets, session revocation and other reasonable measures to protect the Service, Customers and third parties. You must cooperate with proportionate security requests and must not interfere with those controls.

15. Suspension and restriction

We may suspend, downgrade, disable or restrict an Account, protection profile, redirect, webhook, API, Subscription or other functionality where we reasonably believe that:

(a) you have breached the Agreement, failed to pay amounts due, exceeded or attempted to bypass Plan limits, or used the Service outside its intended purpose;

(b) the Service is being used without adequate authority or in a way that is unlawful, infringing, fraudulent, deceptive, unsafe or harmful;

(c) continued access creates a material security, privacy, provider, payment, operational, reputational or third-party risk;

(d) a competent authority, court, provider or applicable law requires or reasonably necessitates the action;

(e) we need to investigate a credible complaint, suspected compromise, disputed domain, false positive, chargeback or unauthorised configuration; or

(f) an urgent technical condition threatens the Service, another Customer, a provider or a third party.

Where a breach is capable of remedy and does not create an immediate legal, security, payment, provider or third-party risk, we will normally provide notice and a reasonable opportunity to remedy the breach before terminating the Account. Where practicable and lawful, and where doing so would not create material risk, we will notify you of the reason for and expected scope of a suspension or restriction. We will restore affected access when the basis for the action has been resolved, where reasonably possible.

Suspension does not relieve you of payment obligations that accrued before suspension or charges for a period during which paid Service access continued, except where mandatory law or the Refund & Cancellation Policy provides otherwise.

16. Cancellation, termination, data export and survival

You may cancel a paid Subscription using the cancellation method available in the dashboard, the Lemon Squeezy customer portal or another method identified at checkout. Cancellation stops future renewal but ordinarily leaves paid access available until the end of the current Billing Period. Unless mandatory law or the Refund & Cancellation Policy provides otherwise, ordinary cancellation does not produce a pro-rata refund for the unused part of the current Billing Period.

You may stop using the Starter free tier at any time. Cancellation or expiry of a paid Subscription may downgrade the Account to Starter; it does not automatically delete the Account, protection profiles or associated data. The profile-activation and feature effects of a downgrade are described in Section 7.

We may terminate an Account or affected Service access immediately for a material breach, unlawful or unauthorised use, fraud, misuse, serious security risk, repeated or unresolved non-payment, material provider requirement, or circumstances in which continued performance would be unlawful or materially harmful. Where a remediable breach does not require immediate action, we will normally provide a reasonable opportunity to cure it.

We may terminate the Service or an Account for operational or commercial convenience by providing reasonable advance notice, unless a shorter period is reasonably necessary because of law, security, insolvency, provider termination or circumstances beyond our reasonable control. If we terminate a paid Subscription for convenience before the end of a paid Billing Period, and termination is not caused by the Customer's breach, misuse or payment failure, the Customer will be entitled to a pro-rata refund for the unused portion of that Billing Period. For Consumers, termination is subject to mandatory Consumer law and does not limit statutory conformity, refund, withdrawal, termination or data-retrieval rights.

If the Account or the Customer's access to the Service is terminated, as distinct from ordinary Subscription cancellation, expiry or downgrade to the free tier, the right to access and use the affected Service ends and active protection profiles, redirects, webhooks, API access and other functionality may be disabled.

Cancellation of a Subscription does not automatically delete the Account or associated data. For Customer Personal Data processed on your behalf, return and deletion are governed by the DPA. For other personal data, the Privacy Policy applies.

Self-service Account deletion is available in Settings and requires explicit confirmation by entering the exact Account email address. A verified deletion removes the Account and associated data from the active database synchronously. Database backups are automatically rotated within fourteen (14) days. A separate, access-restricted deletion ledger containing only a keyed cryptographic hash (HMAC or equivalent) of the deleted Account email address and the deletion date is retained for thirty (30) days and is used solely to identify and automatically re-delete an Account that reappears after restoration. Further retention details are stated in the Privacy Policy and DPA.

After termination of the Account or relevant Service access, you must stop using the affected Service and remove or disable Protection Snippets, API credentials and integrations that are no longer authorised for use. This obligation does not apply merely because a paid Subscription has downgraded to the free tier and applicable free-tier functionality remains authorised. We are not responsible for the continued presence or operation of Customer-installed code after the corresponding right to use it has ended.

Subject to the EU Data Act Addendum and any mandatory right to retrieve data, where dashboard export functionality remains available and no legal, security or abuse-prevention restriction applies, you should export required Customer Data before termination. If we terminate the Service for convenience, we will use reasonable efforts to provide a reasonable export period stated in the termination notice, taking into account available functionality and circumstances. Any return right under the DPA and any mandatory Consumer right to retrieve data remain unaffected.

Where mandatory law governing digital services applies and a Consumer validly terminates the contract because of non-conformity or a qualifying Service modification, PageShield will, upon request and subject to the statutory exceptions, make available without charge or impediment any non-personal content supplied or created by that Consumer when using the Service. Where Romanian law applies, this will be provided within a reasonable period not exceeding fifteen (15) calendar days from the request, in a commonly used and machine-readable format. Personal data is handled separately under the Privacy Policy, the DPA and applicable data-protection law, and this Consumer retrieval right is distinct from switching under the EU Data Act Addendum.

You are responsible for using the available product CSV export while it remains available under the applicable paid Plan, or other available functionality, to maintain independent copies of data that you consider legally, commercially or operationally important, including before a downgrade, Account deletion or Subscription expiry. Where the relevant functionality is enabled and has generated retained records, the product export package includes, for retained Detection Events, approximate country, approximate city and Classification Results, and includes customer-facing Notification Suppression Rule records with available rule scope and lifecycle metadata, whether in the Detection Event CSV or a separate rules CSV. Any exported rule identifier is a separate non-secret record identifier and not the internal HMAC-derived matching value. Raw source IP addresses, transient ASN values, internal data-centre/residential signals, internal ASN lists, HMAC keys or secrets, HMAC-derived matching values, rotating salts and internal classification or matching logic are not included. The precise field names and file arrangement are described in the then-current export schema and documentation. CSV export is not available on Starter. The Service is not intended to be your sole system of record, backup or evidence repository. This responsibility does not limit the EU Data Act Addendum, a statutory Consumer retrieval right, a data-protection right or any return obligation that PageShield has under the DPA.

Provisions that by their nature should survive termination will survive, including provisions concerning accrued payment obligations, intellectual property, confidentiality, disclaimers, limitation of liability, indemnity, governing law and jurisdiction.

16A. EU Data Act Addendum

To the extent that Chapter VI of Regulation (EU) 2023/2854 (the EU Data Act) applies to PageShield, the relevant Service or the Customer relationship, the PageShield EU Data Act Addendum made available with these Terms and through the legal section of https://pageshield.io forms part of the agreement. The Addendum sets out the applicable switching, data portability, transition, retrieval, deletion, exit-support and cooperation terms.

The EU Data Act Addendum applies only within its stated scope and does not constitute an unconditional acknowledgement that every PageShield feature, Plan or Customer relationship qualifies as a data processing service or is otherwise subject to Chapter VI of the EU Data Act.

17. Business Customer indemnity

This Section applies only to Business Customers.

To the maximum extent permitted by applicable law, a Business Customer will defend, indemnify and hold harmless CRAFTAC SRL, its officers, employees, contractors and agents from third-party claims, damages, liabilities, administrative penalties to the extent lawfully recoverable from the Business Customer, costs and reasonable legal fees, in each case to the extent directly caused by:

(a) the Business Customer's unlawful website, content, products, services, offers or business practices;

(b) the Business Customer's unauthorised installation, configuration, use or misuse of the Service;

(c) the Business Customer's lack of rights or authority over a Protected Domain, Protected Page, Redirect Destination, webhook endpoint or other configured property;

(d) the Business Customer's material breach of these Terms or the DPA; or

(e) the Business Customer's violation of applicable law or third-party rights.

This indemnity does not apply to the extent that a claim was caused by CRAFTAC SRL's breach of these Terms, negligence, fraud, wilful misconduct or violation of applicable law.

We will provide reasonable notice of an indemnified claim and reasonable cooperation. The Business Customer may control the defence with counsel reasonably acceptable to us, provided that we may participate at our own expense and the Business Customer may not enter into a settlement that admits liability by, imposes obligations on or materially affects CRAFTAC SRL without our prior written consent, not to be unreasonably withheld.

18. Disclaimers

The disclaimers in this Section apply to Business Customers to the maximum extent permitted by law. Consumers retain all mandatory statutory rights relating to the supply, conformity, performance and remedies applicable to digital services. Nothing in this Section excludes or restricts those rights.

For Business Customers, the Service is provided "as is" and "as available" without warranties, conditions or representations of any kind, whether express, implied, statutory or otherwise, including merchantability, satisfactory quality, fitness for a particular purpose, reasonable care and skill, title, quiet enjoyment and non-infringement, to the maximum extent permitted by applicable law.

We do not warrant that the Service will meet your requirements, detect every cloned page, redirect every visitor, prevent all abuse, operate without interruption, be compatible with every browser or third-party platform, preserve every record, comply with every law applicable to your business or produce any particular commercial result.

Nothing in this Section limits security obligations expressly set out in the DPA or required by applicable law.

19. Limitation of liability

For Business Customers, to the maximum extent permitted by applicable law, CRAFTAC SRL, its officers, employees, contractors, agents and affiliates will not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profit, revenue, business opportunity, goodwill, reputation, anticipated savings, traffic, conversions, data or business interruption.

This limitation includes losses arising from undetected clones, failed redirects, missed Heartbeats, misconfigured redirects, downtime, browser behaviour, third-party interference, Customer configuration, unauthorised copying, competitor behaviour, platform action or failure, provider outages, payment failures, webhook destinations or Customer legal non-compliance.

For Business Customers, to the extent liability is not excluded above, PageShield's total aggregate liability for all claims arising out of or relating to the Agreement or the Service will not exceed the greater of (a) EUR 100 and (b) the fees paid or payable for the affected Service during the six (6) months immediately preceding the first event giving rise to liability.

For Consumers, our liability is subject only to limitations permitted by mandatory applicable law.

Nothing in these Terms excludes or limits liability for fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence, or any other liability that cannot lawfully be excluded or limited.

20. Confidentiality and feedback

Each party may receive non-public commercial, technical, operational or security information belonging to the other party. The receiving party will use such information only for the purposes of the contractual relationship and will protect it using at least reasonable care.

This obligation does not apply to information that is public through no breach of these Terms, was lawfully known before disclosure, is independently developed without use of the confidential information, or is lawfully received from a third party without a confidentiality restriction.

A receiving party may disclose confidential information where required by law, court order or competent authority, provided that, where lawful and reasonably practicable, it gives prior notice and discloses only the information required. PageShield may disclose information to employees, contractors, Affiliates, providers and professional advisers who need it for the Service or legal purposes and are bound by appropriate confidentiality obligations.

If you provide feedback, ideas or suggestions regarding the Service, you grant PageShield a perpetual, irrevocable, worldwide, royalty-free right to use and incorporate them without restriction or payment. PageShield will not publicly identify you as the source without permission.

21. Governing law, jurisdiction and general terms

These Terms and any non-contractual obligations arising from them are governed by Romanian law, without regard to conflict-of-law rules. If you are a Consumer, this choice does not deprive you of mandatory protections available under the law of your habitual residence.

For Business Customers, the courts with jurisdiction in Iasi, Romania will have exclusive jurisdiction over disputes arising out of or relating to the Agreement, unless the parties agree otherwise in writing or mandatory law requires a different forum. A Consumer may bring proceedings in any court available under mandatory Consumer law and may be sued only in a forum permitted by that law.

Consumers should first submit complaints to support@pageshield.io. If a complaint cannot be resolved directly, PageShield will provide, on a durable medium and where required by law, information about the competent alternative dispute resolution entity and will state whether PageShield is required or willing to participate in the relevant procedure. Information about the Romanian National Authority for Consumer Protection (ANPC) alternative dispute resolution mechanism is available at https://reclamatiisal.anpc.ro/. This paragraph does not require a Consumer to use alternative dispute resolution before bringing proceedings and does not limit any mandatory right.

You may not assign, transfer or novate the Agreement without our prior written consent. We may assign or transfer it to an Affiliate or in connection with a merger, reorganisation, financing, sale of assets or transfer of the Service, provided that the assignment does not reduce mandatory Consumer rights or materially reduce the contractual protections applicable to an active paid Subscription.

Notices to PageShield may be sent to support@pageshield.io, unless the Agreement specifies another channel for a particular notice. We may send notices to the email associated with your Account, through the dashboard, in-app, at checkout or by another durable electronic method. You are responsible for keeping your Account email address current and monitoring Service notices.

Neither party will be responsible for delay, failure or degradation caused by events beyond its reasonable control, including internet or hosting failures, provider outages, cyberattacks, denial-of-service attacks, browser or platform changes, regulatory action, labour disputes, natural disasters, war, civil unrest, epidemics, governmental restrictions or major infrastructure failures. The affected party must take reasonable steps to mitigate the effects and resume performance. This provision does not excuse payment obligations accrued before the event, mandatory duties that cannot lawfully be excluded, or obligations - including reasonable security, confidentiality and incident-response measures - that remain capable of performance despite the event.

If any provision is held invalid, unlawful or unenforceable, it will be enforced to the maximum extent permitted and, where possible, interpreted or modified to reflect its intended commercial purpose. Remaining provisions remain in effect. A failure or delay in enforcement is not a waiver.

These Terms, together with the Refund & Cancellation Policy, the DPA where applicable, the PageShield EU Data Act Addendum where applicable, and any order or Plan details expressly agreed at checkout, constitute the entire agreement between you and us regarding the Service and supersede prior discussions or communications concerning the same subject matter. This does not exclude pre-contractual information, representations or statutory rights that cannot lawfully be excluded.

Except where mandatory law provides otherwise, the Agreement does not create rights for a person who is not a party. However, officers, employees, contractors, agents and Affiliates expressly protected under Sections 17 and 19 may rely on and enforce those protections to the extent permitted by applicable law.

The parties are independent contractors. The Agreement does not create a partnership, joint venture, employment, fiduciary, agency, franchise or exclusive relationship.

Headings are for convenience only and do not affect interpretation. Words such as "including" and "include" are illustrative and do not limit preceding words.

The English-language version is the controlling version. PageShield may provide translations or jurisdiction-specific notices for convenience or compliance, but a translation does not change the English version except where mandatory applicable law requires a local-language version or gives that version controlling effect.

You agree that contractual notices, records, acceptances and communications may be provided electronically. Electronic acceptance and records have the same effect as written acceptance and records to the extent permitted by applicable law.

22. Changes to these Terms

We may update these Terms where reasonably necessary to reflect changes in the Service, law, security, providers, payment arrangements or technical architecture, or to prevent fraud, abuse or material operational risk. An incorporated contractual document may be updated only in accordance with applicable law, its valid update mechanism and the protections in this Section.

We will provide reasonable advance notice of material changes by email, dashboard or in-app notice, or another durable electronic method, unless an earlier effective date is reasonably required by law, security, fraud or abuse prevention, or an urgent provider requirement. Material changes will not apply retroactively.

For Business Customers, an adverse material change to a paid Subscription will normally apply no earlier than the next renewal date. If it must apply during an active paid Billing Period and materially reduces core paid functionality, the Business Customer may terminate and request a pro-rata refund for the unused portion.

For Consumers receiving the Service continuously over a period, a modification going beyond what is necessary to maintain conformity will be made only where the Agreement permits it for a valid reason, without additional cost, and after clear and comprehensible information. If the modification negatively affects access to or use of the Service and the impact is not minor, PageShield will provide reasonable advance notice sufficiently before the change takes effect on a durable medium describing the characteristics and date of the change and the Consumer's right to terminate, unless PageShield enables the Consumer to retain the unmodified conforming Service without additional cost. Where Romanian law applies, the Consumer may terminate without cost within thirty (30) days after receiving that information or after the modification takes effect, whichever is later. We will not remove an accrued statutory right, impose a retroactive charge or materially alter a current Consumer contract without the valid basis, notice, consent or remedy required by law.

Continued use after a notified change constitutes acceptance only where permitted by law. If you do not agree to a prospective change, stop using the affected Service and cancel before it takes effect, without limiting any mandatory right. Questions may be sent to support@pageshield.io.

23. Contact

PageShield is operated by CRAFTAC SRL, a limited liability company incorporated under Romanian law, registered with the Romanian Trade Register under no. J22/725/2024, having unique identification code (CUI) 49662167 and its registered office at Str. Bisericii 9, Bl. 65, Sc. A, Et. 4, Ap. 15, Cod 707085, Sat Lunca Cetățuii, Iași County, Romania.

Email: support@pageshield.io

Telephone: +40 770 707 196

General enquiries, complaints and notices for which the Agreement does not prescribe a specific submission channel may be sent using the contact details above.

Home Privacy Policy Refund & Cancellation Policy Data Processing Addendum EU Data Act Addendum Documentation Blog